Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-62062 — Proof-of-concept and lab pack for CVE-2026-62062, an unauthenticated CSRF REST nonce bypass in Elementor 4.3.0-4.3.1 enabling administrator account creation. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-62062
Vulnerability AnalysisExploitationWeb Application ExploitationSecurity VirtualizationWeb SecurityPenetration TestingLabs & Practice
GitHubabraxas/cve-2026-62062

CVE-2026-62062

Proof-of-concept and lab pack for CVE-2026-62062, an unauthenticated CSRF REST nonce bypass in Elementor 4.3.0-4.3.1 enabling administrator account creation.

View Repository
12 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Abraxas Labs — CVE-2026-62062 — WordPress

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  CVE-2026-62062

CVE-2026-62062 — WordPress

WordPress — Elementor Website Builder 4.3.1 — Elementor

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

CVECVE-2026-62062 · CVE.org
CWECWE-352
CVSSHigh: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ProductElementor Website Builder
Affectedall versions through 4.3.1 (inclusive)
Patched4.3.2 and later
Authunauthenticated (see source map)
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only · vendor/client disclosure pack, not a scanner

Advisory (from the source map)

elementor/core/common/modules/events-manager/rest-api/events-proxy-rest-api.php is_own_route_request. 4.3.2 uses rest_route prefix instead of raw REQUEST_URI.


Entry

  • Method: POST
  • Path: /?rest_route=/wp/v2/users&x=elementor/v1/events/
  • Router: Unauthenticated CSRF. Elementor Events_Proxy_REST_API.bypass_nonce_check_for_own_routes on rest_authentication_errors. is_own_route_request strpos REQUEST_URI.
  • Notes: Unauthenticated CVE-2026-62062 CWE-352 Elementor 4.3.1. Witness: 201 JSON slug=csrfadmin-* roles administrator. Control POST without the URI substring is rest_cookie_invalid_nonce. Not a reverse shell.

Call chain

  • victim admin has wordpress_logged_in cookie
  • POST /?rest_route=/wp/v2/users&x=elementor/v1/events/ JSON roles=administrator, no X-WP-Nonce
  • Events_Proxy_REST_API.is_own_route_request strpos REQUEST_URI
  • rest_authentication_errors returns true; rest_cookie_check_errors skips nonce
  • wp/v2/users create_item as the victim administrator

Lab preconditions

  • Elementor 4.3.0 or 4.3.1 active
  • Administrator cookie session (UI:R) visits the URL / their browser sends the POST

Witness

POST with admin cookies and no nonce: 401 without URI substring; 201 administrator user with x=elementor/v1/events/.

Not success

  • 401 rest_cookie_invalid_nonce on the attack URL
  • user created without the URI bypass
  • reverse shell

Patch / remediation

Do this first: Update Elementor Website Builder to 4.3.2 or newer.

Verify after upgrade

  • Re-run CVE-2026-62062-Abraxas-Labs.py against the patched build: the mapped witness must not appear.
  • Confirm the vendor advisory / changeset in the deployed tree (see references).
  • A WAF signature is delay, not a patch.

If you cannot update immediately

  • Disable or isolate the affected component.
  • Hunt for the witness condition on production (new privileged users, unexpected files, injected rows — whatever this CVE's map names).

Reproduction (authorized lab)

Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.

root@kitploit:~
python3 CVE-2026-62062-Abraxas-Labs.py

Success is the witness above in the response body. Generic 200 HTML is not it.


Lab images

Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.

  • lab/docker-compose.yml
  • lab/Dockerfile
root@kitploit:~
cd lab
docker compose up --force-recreate

Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.


References

  • CVE-2026-62062 · NVD

  • CVE-2026-62062 · CVE.org

  • www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elementor/elementor-website-builder-430-431-cross-site-request-forgery-via-rest-nonce-bypass-to-privilege-escalation

  • patchstack.com/database/wordpress/plugin/elementor/vulnerability/wordpress-elementor-website-builder-plugin-4-3-1-cross-site-request-forgery-csrf-vulnerability

  • www.cve.org/CVERecord?id=CVE-2026-62062

  • patchstack.com/database/wordpress/plugin/elementor/vulnerability/wordpress-elementor-website-builder-plugin-4-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve

  • Plugin directory: elementor

  • Trac browser: plugins.trac.wordpress.org/elementor

  • SVN tags: plugins.svn.wordpress.org/elementor

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


Records (structured)

root@kitploit:~
# CVE-2026-62062

CWE: CWE-352
CVSS: High 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Patchstack / Wordfence).

## Description

Elementor 4.3.0–4.3.1 skips WordPress REST cookie nonce validation when `$_SERVER['REQUEST_URI']` contains `elementor/v1/events/`. An unauthenticated attacker who tricks an administrator cookie session into requesting a REST URL with that substring can perform any REST action the victim’s role allows, including creating an administrator.

## Product

Elementor Website Builder 4.3.1 (fixed in 4.3.2). Free plugin on wordpress.org. Lab oracle is CSRF-style REST user create, not RCE.

License

This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.


Disclaimer

This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Download Tool